Open source licensing alone is insufficient for digital sovereignty — governance is the critical missing piece. OpenStack TC Chair Goutham Pacha Ravi argues that who governs software matters as much as where data resides. He outlines three problematic open source models (open core, single-vendor, CLA-gated) that undermine sovereignty, using Terraform, Redis, and MongoDB as cautionary examples. OpenStack's governance counters these risks through anti-capture rules: no single org can hold more than 50% of TC seats, all projects must use Apache 2.0, the CLA was replaced with a DCO (effective July 2025) so contributors retain copyright, and all development happens in public. With 40% European contributors and adoption in EU sovereign cloud initiatives backed by €180M in EC contracts, OpenStack is presented as a model for genuine digital sovereignty through open governance.

9m read timeFrom allthingsopen.org
Post cover image
Table of contents
Most digital sovereignty strategies focus on where data lives. Here's why who governs the software matters more.When open source licensing isn’t enough for digital sovereigntyHow OpenStack’s governance protects against vendor captureWhat 40% European contributors actually means for digital sovereigntyMore from We Love Open SourceAbout the Author
33 Impressions